Libiberty
Vendor:
First CVE: Sep 5, 2012 · Active for 13 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libiberty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2012
13 years ago
Most Recent CVE
Feb 24, 2017
3,437 days ago
CVE Severity & Scoring
Libiberty10 CVEs
80%
20%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (80.0%)
Network1 (10.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None2 (20.0%)
Unknown1 (10.0%)
Required7 (70.0%)
Privileges Required
Low0 (0.0%)
High1 (10.0%)
None8 (80.0%)
Unknown1 (10.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2226HIGH Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer over | Feb 24, 2017 | 7.8 | 40 | NO | YES |
CVE-2016-6131HIGH The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled t | Feb 7, 2017 | 7.5 | 28 | NO | NO |
CVE-2012-3509MEDIUM Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow re | Sep 5, 2012 | 5.0 | 22 | NO | NO |
CVE-2016-4493MEDIUM The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and cra | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4491MEDIUM The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers inf | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4490MEDIUM Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4489MEDIUM Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the " | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4488MEDIUM Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec." | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4487MEDIUM Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec." | Feb 24, 2017 | 5.5 | 21 | NO | NO |
CVE-2016-4492MEDIUM Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary. | Feb 24, 2017 | 4.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Libiberty
Top CWEs
Versions
No cataloged versions.